MAL-2026-12206
Dashboard / Malicious Package / MAL-2026-12206
MAL-2026-12206
Summary: Malicious code in simple-date-formatter-util-8 (npm)
Details: Source: amazon-inspector (28db20339e88b1f37da250a38c838eae62b32419a4c36e806b7c6367671f064c) package.json declares a postinstall lifecycle script that runs curl against the hardcoded bare-IP endpoint http://124.221.154.135/pre, passing the installer's hostname and username as query parameters ($(hostname), $(whoami)). The package presents itself as a trivial date-formatting utility, a purpose that has no need for network I/O at install time. The behavior fires automatically on npm install and leaks installer host identity to a non-first-party attacker-controlled endpoint.
Affected packages
Package
Name: simple-date-formatter-util-8
Purl: pkg:npm/simple-date-formatter-util-8
Affected ranges
Type: N/A
Events:
